Identity and access
Administrator roles and how many exist, MFA enforcement state, legacy authentication protocols still enabled, dormant and orphaned accounts, and password policy.
Cloud security configuration is the review and hardening of the settings that govern identity, sharing, and administration inside platforms like Google Workspace, Microsoft 365, Dropbox, and Azure. Most cloud breaches in small businesses come from a misconfigured setting, not from a sophisticated exploit.
Administrator roles and how many exist, MFA enforcement state, legacy authentication protocols still enabled, dormant and orphaned accounts, and password policy.
OAuth applications connected to your tenant, what scopes they hold, and which ones nobody remembers approving.
Default sharing scope for files and drives, links set to anyone-with-the-link, external collaborators with standing access, and shared mailboxes.
SPF, DKIM, and DMARC records, forwarding rules that send mail outside the organization, and inbox rules created by an attacker after a compromise.
Whether audit logs are turned on, how long they are retained, and whether anyone would see an alert if an account were taken over tonight.
Which devices can reach company data, whether unmanaged personal devices are included, and what happens when someone leaves.
We start with a read-only administrative view under NDA. Nothing is changed during the assessment phase.
Current settings are compared against platform hardening guidance and the controls that map to NIST CSF and ISO 27001.
Each finding is ranked by business risk, not by severity score alone, with the exact setting and the exact remediation written out.
We apply the changes with you, in a sequence that does not break how your team actually works, or hand the runbook to your IT provider.
Settings are verified after the change, and the configuration baseline is documented so drift is visible later.